From: "Dmitry V. Sabanin" Date: 2004-05-12T10:52:12+09:00 Subject: Re: [OT] Web, Cookies and Sessions On Wednesday 12 May 2004 03:03, Eric Schwartz wrote: > "Kirk Haines" writes: > > I don't think there's any magic other than trying to deliver a cookie > > when they first arrive at your site and then seeing if it's there on the > > next transaction. > > You can get a bit sneaky, if you're willing to trust your users a > little. OTOH, if you're using cookies, you're *already* trusting the > user to not be malicious, at least a bit. The algorithm looks like: > > On any page load: > 1) Check if there's a cookie. If so, all is well, exit. > 2) Check if HTTP_REFERER (note spelling) comes from the same site. > If not, then set a cookie. This is it! :-) As I said, I overlooked the obvious thing. Thank you very much! > 3) At this point, you know you don't have a cookie, and the user > claims to have already been on your site, which means they won't > accept cookies, so set your rewrite_url flag. > > Note that this algorithm is riddled with places for assumptions to be > proven false, the most obvious of which is that HTTP_REFERER is > trivially spoofable. It also doesn't account for situations where you > only want to set a cookie if the visitor visits a certain subset of > URIs. But then, cookies themselves are trivially editable from the > client side as well, so that's not really so bad. > > Also, note that this isn't really different from what you said, Kirk; > I just thought of it as I was reading your post. Think of it more as > an expansion on a theme. Really, it's. > But in any event, this really has nothing to do with Ruby at all, so > I'm setting followups to CIWAC, where they know about this sort of > thing, and are probably going to be able to give the OP a better > answer than most people here can. What's CIWAC? > > -=Eric Thanks for answers Erik, Kirk. -- sdmitry -=- Dmitry V. Sabanin MuraveyLabs. Spam Here -> postmaster@sco.com